2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-1556 | CRITICAL | 9.8 | 0.6% | Feb 22, 2025 | A vulnerability, which was classified as problematic, has been found in westboy CicadasCMS 1.0. This issue affects some ... |
| CVE-2025-1510 | CRITICAL | 9.8 | 0.6% | Feb 22, 2025 | The The Custom Post Type Date Archives plugin for WordPress is vulnerable to arbitrary shortcode execution in all versio... |
| CVE-2025-1509 | CRITICAL | 9.8 | 0.6% | Feb 22, 2025 | The The Show Me The Cookies plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, a... |
| CVE-2025-27105 | CRITICAL | 9.1 | 0.5% | Feb 21, 2025 | vyper is a Pythonic Smart Contract Language for the EVM. Vyper handles AugAssign statements by first caching the target ... |
| CVE-2025-1555 | CRITICAL | 9.8 | 0.7% | Feb 21, 2025 | A vulnerability classified as critical was found in hzmanyun Education and Training System 3.1.1. This vulnerability aff... |
| CVE-2025-26014 | CRITICAL | 9.8 | 1.0% | Feb 21, 2025 | A Remote Code Execution (RCE) vulnerability in Loggrove v.1.0 allows a remote attacker to execute arbitrary code via the... |
| CVE-2025-1539 | CRITICAL | 9.8 | 1.5% | Feb 21, 2025 | A vulnerability, which was classified as critical, has been found in D-Link DAP-1320 1.00. Affected by this issue is the... |
| CVE-2025-0838 | CRITICAL | 9.8 | 0.6% | Feb 21, 2025 | There exists a heap buffer overflow vulnerable in Abseil-cpp. The sized constructors, reserve(), and rehash() methods of... |
| CVE-2025-26794 | CRITICAL | 9.8 | 75.8% | Feb 21, 2025 | Exim 4.98 before 4.98.1, when SQLite hints and ETRN serialization are used, allows remote SQL injection. (Resolving SQL ... |
| CVE-2025-25678 | CRITICAL | 9.8 | 0.4% | Feb 20, 2025 | Tenda i12 V1.0.0.10(3805) was discovered to contain a buffer overflow via the funcpara1 parameter in the formSetCfm func... |
| CVE-2025-25676 | CRITICAL | 9.8 | 0.4% | Feb 20, 2025 | Tenda i12 V1.0.0.10(3805) was discovered to contain a buffer overflow via the list parameter in the formwrlSSIDset funct... |
| CVE-2025-25675 | CRITICAL | 9.8 | 1.2% | Feb 20, 2025 | Tenda AC10 V1.0 V15.03.06.23 has a command injection vulnerablility located in the formexeCommand function. The str vari... |
| CVE-2025-25674 | CRITICAL | 9.8 | 0.4% | Feb 20, 2025 | Tenda AC10 V1.0 V15.03.06.23 is vulnerable to Buffer Overflow in form_fast_setting_wifi_set via the parameter ssid. |
| CVE-2025-25668 | CRITICAL | 9.8 | 0.5% | Feb 20, 2025 | Tenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the shareSpeed parameter in the sub_47D878 funct... |
| CVE-2025-25667 | CRITICAL | 9.8 | 0.5% | Feb 20, 2025 | Tenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the urls parameter in the function get_parentCon... |
| CVE-2025-25664 | CRITICAL | 9.8 | 0.5% | Feb 20, 2025 | Tenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the shareSpeed parameter in the sub_49E098 funct... |
| CVE-2025-25663 | CRITICAL | 9.8 | 0.5% | Feb 20, 2025 | A vulnerability was found in Tenda AC8V4 V16.03.34.06. Affected is the function SUB_0046AC38 of the file /goform/WifiExt... |
| CVE-2025-25662 | CRITICAL | 9.8 | 0.4% | Feb 20, 2025 | Tenda O4 V3.0 V1.0.0.10(2936) is vulnerable to Buffer Overflow in the function SafeSetMacFilter of the file /goform/setM... |
| CVE-2025-24893 | CRITICAL | 9.8 | 99.9% | Feb 20, 2025 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any guest can p... |
| CVE-2025-1265 | CRITICAL | 9.9 | 1.3% | Feb 20, 2025 | An OS command injection vulnerability exists in Vinci Protocol Analyzer that could allow an attacker to escalate privile... |
| CVE-2025-27096 | CRITICAL | 9.8 | 0.5% | Feb 20, 2025 | WeGIA is a Web Manager for Institutions with a focus on Portuguese language. A SQL Injection vulnerability was discovere... |
| CVE-2025-20059 | CRITICAL | 9.2 | 0.8% | Feb 20, 2025 | Relative Path Traversal vulnerability in Ping Identity PingAM Java Policy Agent allows Parameter Injection.This issue af... |
| CVE-2025-0868 | CRITICAL | 9.3 | 15.1% | Feb 20, 2025 | A vulnerability, that could result in Remote Code Execution (RCE), has been found in DocsGPT. Due to improper parsing of... |
| CVE-2025-24989 | CRITICAL | 9.8 | 1.7% | Feb 19, 2025 | An improper access control vulnerability in Power Pages allows an unauthorized attacker to elevate privileges over a net... |
| CVE-2025-21355 | CRITICAL | 9.8 | 1.5% | Feb 19, 2025 | Missing Authentication for Critical Function in Microsoft Bing allows an unauthorized attacker to execute code over a ne... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now